CVE-2013-0238

Ircd-hybrid < 8.0.5 - Improper Input Validation

Title source: rule

Description

The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed.

Exploits (1)

exploitdb WORKING POC
by kingcope · perldoslinux
https://www.exploit-db.com/exploits/24951

Scores

EPSS 0.3922
EPSS Percentile 97.3%

Details

CWE
CWE-20
Status published
Products (12)
ircd-hybrid/ircd-hybrid 7.2.0
ircd-hybrid/ircd-hybrid 7.2.1
ircd-hybrid/ircd-hybrid 7.2.2
ircd-hybrid/ircd-hybrid 7.2.3
ircd-hybrid/ircd-hybrid 7.3.0 (2 CPE variants)
ircd-hybrid/ircd-hybrid 7.3.1
ircd-hybrid/ircd-hybrid 8.0.0 (5 CPE variants)
ircd-hybrid/ircd-hybrid 8.0.1
ircd-hybrid/ircd-hybrid 8.0.2
ircd-hybrid/ircd-hybrid 8.0.3
... and 2 more
Published Feb 13, 2013
Tracked Since Feb 18, 2026